By 15 December 2026, non-corporate Commonwealth entities covered by the Policy for the responsible use of AI in government, subject to its stated exceptions, must have implemented the requirement to assess in-scope AI use cases.

The deadline does not mean every existing AI use case must have completed a full assessment by that date. Existing use cases that have not yet been assessed must be reviewed for scope and have relevant policy actions applied by 30 April 2027. However, agencies should have the assessment capability operating by December 2026 and use it for new in-scope AI designs.

This article provides practical guidance, not legal advice. Agencies and suppliers should obtain legal, privacy, security and technical advice for their circumstances.

The practical message for agencies and suppliers

  • Agencies need a working governance process, not only a downloaded template.
  • Project teams need to assess AI during design, before major choices become difficult to reverse.
  • Suppliers need evidence that helps the agency understand the system, test its claims and manage it after deployment.
  • Existing and new use cases need different transition plans, owners and deadlines.

What the December 2026 deadline means

Version 2.0 of the policy took effect on 15 December 2025. It is mandatory for non-corporate Commonwealth entities, subject to the policy’s stated exclusions. Corporate Commonwealth entities are encouraged to apply it.

The policy requires more than an assessment form. Its broader requirements include a strategic approach to AI adoption, an operational process for responsible use, accountable officials and use-case owners, an internal register, staff training, proportionate oversight, monitoring and reassessment after material change.

Agencies must assess every new AI use case against the policy’s scope criteria during design. If it is in scope, the impact assessment should begin during design, be finalised before deployment and include agreed risk treatments. Treating 15 December as a last-minute form-completion exercise risks creating a backlog without improving decisions.

Which AI use cases are in scope?

An AI use case is in scope if any of the policy’s criteria apply. Context matters: a modest tool can become in scope when its use changes, such as when a writing assistant begins processing sensitive case files or contributing to decisions about individuals.

  • Use, misuse or failure could cause more than insignificant harm.
  • AI will materially influence an administrative decision affecting people, communities, organisations, the environment or collective cultural rights.
  • The public may interact directly with AI, or be significantly affected by its output, without human review.
  • The system is designed to use personal information, sensitive information or security-classified information.
  • The DTA identifies the use case as an elevated-risk use.

Recruitment, discretionary automated decisions, justice, law enforcement, health, education and critical infrastructure require careful consideration. They are not automatically high risk, but their context can increase the likelihood or consequence of harm. Incidental low-risk functionality such as grammar assistance may fall outside the policy where none of the criteria apply, but the scope decision should still be documented.

What the assessment involves

The Australian Government AI impact assessment tool contains 12 sections. Every in-scope use case begins with a threshold assessment covering basic information, purpose and expected benefits, inherent risk, and the threshold outcome.

If all inherent risks are rated low, the approving officer can endorse concluding the assessment at section 4, provided suitable monitoring, evaluation and revalidation arrangements remain in place. If any inherent risk is medium or high, the team proceeds through sections 5 to 12.

  • Fairness.
  • Reliability and safety.
  • Privacy protection and security.
  • Transparency and explainability.
  • Contestability.
  • Human-centred values.
  • Accountability.
  • Use-case review, residual risk and next steps.

The overall inherent-risk rating uses the highest risk identified across the assessment categories. A high inherent-risk use case attracts additional governance: it must be reported to the agency’s accountable official and governed through an appropriate board or senior executive. If deployed, it must be reported to the DTA and reviewed at least annually.

Build assessment into delivery, not around it

  • During discovery: define the operational problem, intended public value, affected people, baseline, AI role and likely scope status.
  • During design and procurement: appoint accountable roles, map data and integrations, define human review, identify foreseeable harms and turn them into testable requirements.
  • Before deployment: complete the applicable assessment sections, apply and test treatments, record residual risk, confirm monitoring and fallback, obtain approval and update the register.
  • During operation: monitor performance, errors, overrides, complaints and incidents, then revalidate after material changes to scope, data, models, suppliers or operation.

What suppliers should prepare

The policy places accountability on the agency. A supplier does not complete the agency’s governance obligations for it. However, suppliers may be required through an approach to market or contract to provide evidence that makes a defensible assessment possible.

  • The proposed system, models, versions and intended use.
  • Known limitations, foreseeable misuse and failure modes.
  • Data used for training, tuning, grounding and operation where relevant.
  • How government data is stored, processed, retained and protected.
  • The role of subcontractors, model providers and other supply-chain participants.
  • Testing for accuracy, reliability, safety, security, bias and unfair outcomes.
  • How outputs can be logged, traced, explained and reviewed.
  • Human oversight, escalation, circuit-breaker, fallback and rollback arrangements.
  • How model or service changes will be disclosed and evaluated.
  • Monitoring metrics, incident support and ongoing assurance responsibilities.
  • Intellectual-property and data-use arrangements.

Suppliers that prepare this information before a tender is released can respond more clearly and reduce clarification cycles later. Government buyers should ensure those responsibilities survive into contract management rather than ending at vendor selection.

Example: AI-assisted grants triage

Consider a hypothetical agency procuring an AI service to classify grant applications, identify missing information and prepare a summary for an assessment officer. It is likely to require an impact assessment because it processes personal information and could materially influence an administrative decision.

The agency would need to define whether AI only prepares information or also recommends priority or eligibility, which officer remains responsible, how applicants are told about AI use, how they can correct information or contest an outcome, and what happens when evidence is incomplete or outside the model’s capability.

  • A system and data-flow description.
  • Model and version information.
  • Representative test results and known limitations.
  • Source traceability for generated summaries.
  • Logging of AI output, officer corrections and overrides.
  • Security, privacy and data-location information.
  • Change notifications and a safe rollback process.

A sensible acceptance test would include ordinary applications, incomplete applications, unusual evidence and applications from people with different accessibility or language needs. It should show not only average accuracy, but where errors occur and whether human review catches them.

The assessment does not prevent the use case. It helps the agency decide whether the benefits justify the risks and which controls are needed before deployment.

A practical readiness timeline

  • Now to September 2026: inventory AI use cases, establish an intake and scope-triage process, confirm roles, identify likely full assessments and add evidence requirements to current procurements.
  • October 2026: pilot the assessment process on representative use cases, resolve ownership and evidence gaps, issue structured requests to suppliers, and train project, procurement, risk and assurance teams.
  • November to 15 December 2026: complete assessments required for new in-scope deployments, escalate high-risk cases and confirm monitoring, revalidation and record-keeping processes.
  • 16 December 2026 to 30 April 2027: work through the existing-use-case backlog, apply relevant policy actions, review contracts with evidence gaps and revalidate material changes.

Does every use of AI need the full 12-section assessment?

No. Every new use case must be checked against the in-scope criteria. An in-scope case begins with sections 1 to 4. If all inherent risks are low, it may conclude at the threshold stage with approving-officer endorsement and suitable monitoring. Medium or high inherent risks require the full assessment.

Must every existing use case be completed by 15 December 2026?

No. The policy gives agencies until 30 April 2027 to determine whether previously unassessed existing use cases are in scope and apply relevant actions. The December deadline still matters because the agency’s assessment process must be operational for new in-scope work.

Can an agency use its own assessment process?

Yes. An internal process can be used if it incorporates all provisions of the Australian Government tool, operates consistently and produces the same or a higher inherent and residual risk outcome. It must also be adaptable when the government tool changes.

Is the supplier responsible for approving the assessment?

No. Approval and accountability remain with the agency. The supplier’s role is to provide accurate, decision-useful evidence and meet its procurement and contractual obligations.

Does the assessment replace privacy, security or procurement review?

No. The DTA states that the tool complements existing frameworks and does not replace comprehensive risk management. Privacy, security, records, accessibility, procurement, legal and domain-specific obligations still need to be addressed.

Turn the deadline into better delivery

The December requirement should not become a compliance queue disconnected from implementation. Used well, the assessment gives agencies and suppliers a common structure for making AI safer, more testable and easier to operate.

ExIQ helps Australian organisations connect AI strategy, advisory and governance with practical delivery. Explore our work with government and public-sector organisations, read our Australian Government AI assurance framework guide, or contact ExIQ to discuss an assessment-ready AI initiative.